Chapter 3. Live Response - Data Collection

Solutions in this chapter:

  • Prepare the Target Media
  • Format the Drive
  • Gather Volatile Information
  • Acquiring the Image
  • Summary

Introduction

Once on-site at a customer location, it's important to sit down with the customer and find out what has transpired. Understand that this conversation will probably provide you with different information than you may have initially received from any prior triage calls. I am not sure if it has to do with a lack of understanding of the full breadth and depth of the situation, or if the stress of the incident leads to certain details being missed, but from my experience ...

Get UNIX and Linux Forensic Analysis DVD Toolkit now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.